Medical Records Release Automation: Meet the 30-Day Deadline

A records request that misses HIPAA's 30-day deadline is a real compliance risk. Here is the exact timeline, what you can legally charge, and what to automate safely.

Muhammad Qasim HammadAugust 17, 202611 min read

Records Release: Medical Records Release Automation
On this page

A records request that sits in a stack of faxes past the legal deadline is not paperwork sitting around. It is a compliance risk with a real dollar figure attached, and a slow, manual task that nobody at the front desk actually owns. HIPAA's Right of Access rule gives a covered entity 30 days to act on a request, not 30 days to get around to it.

This post gives you the accurate deadline, what you can legally charge, what OCR has actually enforced against practices that missed the clock, and which parts of the records-release workflow you can safely hand to automation. Every figure here is sourced, and nothing here is legal advice: confirm your state's specific rules with counsel before you finalize a fee schedule or a policy.

By the end you will know exactly where the 30-day clock starts, where a fax-based request quietly turns into a liability, and what a real records-release delay has cost a practice that got the timing wrong.

What counts as a medical records release request

A medical records release request, often called an ROI or release-of-information request, is any ask for a copy of a patient's chart: a portal download, a faxed form, a mailed letter, an attorney's subpoena, or an insurer's audit request. Each one starts the same legal clock, no matter how it arrives.

The channel changes the paperwork, not the deadline. A patient logging into your portal, a law firm faxing a signed authorization, and a payer requesting a chart for an audit are all requests for access to or disclosure of protected health information, and HIPAA's timing and fee rules bind the patient-directed ones no matter the format.

In a typical week, the requests a practice sees usually fall into a few buckets:

  • A patient or their personal representative asking for their own chart
  • An attorney or insurance adjuster with a signed authorization, tied to a claim
  • A specialist or referring provider requesting records to continue care
  • A payer or auditor requesting documentation to support a billed claim

Only the first is squarely governed by HIPAA's individual right of access. The others typically move under a signed authorization, a business associate relationship, or a treatment, payment, or operations disclosure, each with its own rules, so it helps to sort a request into the right bucket before you decide how fast it has to move.

Sorting the request also decides who should sign off on it. A straightforward patient request can move through a standard front-desk process end to end. An attorney, payer, or subpoena-backed request usually benefits from a second set of eyes, ideally your named privacy contact, before anything actually leaves the building.

The records-release workflow, step by step

Every records request should move through the same 6-step workflow regardless of channel: receipt, identity and authorization verification, logging with a due date, compiling the records, reviewing them against what was actually authorized, and release. Skipping the verification or logging step is where most delays and mistakes start.

Six-step workflow for a records release request: received, identity verified, logged with due date, compiled, reviewed for scope, releasedThe same six steps whether the request arrives by portal, fax, or certified mail.

The workflow rarely fails at compiling the records themselves. It fails at the edges: nobody verifies identity before promising a timeline, nobody logs the due date the day the request lands, and nobody reviews scope before hitting send, so a request that should take under an hour of real labor stretches across a stack of unopened mail.

A due date that lives only in someone's memory is the single most common point of failure, and it is also the easiest one to fix with a simple log that assigns an owner the day a request arrives.

Compiling the records is rarely a single query. A complete chart often means pulling from the EHR, a separate billing system, and results from a lab or specialist the patient saw elsewhere, and the review-for-scope step exists precisely to catch anything that was never actually authorized before it goes out the door.

The HIPAA Right of Access deadline: 30 days, one extension

HIPAA's Right of Access rule gives a covered entity 30 calendar days to act on a records request, starting the day it arrives. If more time is genuinely needed, one 30-day extension is allowed, but only once, and only with written notice to the requester before the original 30 days run out.

Timeline showing a records request starting a 30-day clock at day zero, a deadline at day 30, and a one-time extension ending at day 60One extension, one time only, with written notice before day 30.

The clock starts the day the request arrives, not the day someone gets to it and not the day a form is technically complete. If a practice needs the extension, the written notice explaining the delay and the new date has to go out before the original 30 days expire, for a 60-day outer limit. A second extension is not available under the federal rule.

This deadline is one piece of a bigger picture. If you have not mapped the rest of it, including BAAs, minimum necessary rules, and breach notification, the wider HIPAA-aware setup this fits inside is worth reading alongside this one.

It is also worth knowing the deadline is not frozen in time. A 2021 proposal to shorten it to 15 days plus a 15-day extension was never finalized, and HHS has signaled it is working on a further proposed rule addressing response timeframes. Treat 30 and 60 days as the current, confirmed numbers, and check for updates before you rely on an older source.

What you can legally charge for a records release

HIPAA limits what a practice can bill to a reasonable, cost-based fee: labor for copying, supplies, and postage. Search and retrieval time is off-limits, and per-page fees are not allowed for electronically maintained records. A flat fee of up to $6.50 is an optional shortcut, not a universal cap.

Fee methodWhat it can includeLimit
Actual costLabor for copying, supplies, postageMust reflect real cost, itemized on request
Average cost scheduleA standard rate calculated once from actual labor costsCannot include search or retrieval time
Flat fee, electronic onlyA flat rate for an electronic copy of an electronic recordCapped at $6.50, optional, not mandatory

Most practices are better off picking one method and applying it consistently rather than calculating a fresh number for every request. The $6.50 flat option exists exactly for that reason: it is a shortcut a covered entity may choose, not a fee every requester can demand or every practice must charge.

Where these requests still bottleneck: fax, portals, and paper

Most of the workflow above sounds simple on paper, and most of it still breaks in practice at the intake step. A large share of records requests still arrive by fax or scanned mail, land in a shared inbox, and sit until someone notices the due date is close, which is exactly where automation earns its keep.

If records requests still arrive by fax in your practice, you are not unusual: fax remains one of the most common intake channels for signed authorizations and attorney requests, precisely because it satisfies signature and delivery expectations that a plain email does not.

This is exactly the kind of intake problem OCR-based document processing is built for: reading a scanned or faxed request, pulling out the requester, the date range, and the authorization details, and logging it with a due date automatically, so nothing sits unopened until someone happens to notice it. Scale changes the math, too: one academic hospital system's monthly ROI volume grew from 278 to 570 requests after it moved to electronic submission, without a matching increase in staff, and at least one records-release vendor claims a 10 to 12 day average turnaround under automation, comfortably inside the 30-day ceiling.

What OCR enforcement says about the cost of getting this wrong

The 30-day deadline is not a suggestion with no teeth behind it. The HHS Office for Civil Rights has brought more than 50 Right of Access enforcement actions since the initiative launched in 2019, and recent settlements show regulators are still actively pursuing practices and health systems that miss the clock.

Four benchmark cards: OCR enforcement actions since 2019, two release-delay settlements, and the flat fee cap for an electronic copyPublished figures, each sourced. Verify before you repeat them.

Two recent settlements show the range. Concentra, Inc. paid $112,500 in December 2025 after OCR found it failed to provide timely access to a patient's records within 30 days. A Florida health system paid $60,000 in early 2025 after a patient had to file a complaint with OCR before finally receiving records requested through multiple channels.

Most of these cases start the same way: a patient who never got their records within the deadline files a complaint directly with OCR, not a routine audit that happens to find the problem. That means the practices most exposed are not necessarily the ones with the worst systems. They are the ones whose patients got frustrated enough to complain.

Automate the mechanical steps, keep a human on the judgment calls

Not every part of this workflow deserves the same treatment. Logging a request, tracking its due date, and sorting incoming portal or fax requests are mechanical tasks that automation and OCR handle well. Verifying identity, reading a subpoena, and deciding what a third party is actually entitled to still need a trained person.

This split is the same one that shows up across front-desk automation generally: where an AI receptionist fits and where it stops applies just as directly to records requests as it does to phone calls. Automate the routine, keep a trained person on anything that requires judgment.

Get an honest picture of your records-release load

Before you buy or build anything, route your own next 10 records requests through a simple decision path: verify identity, check whether it is a straightforward copy, flag anything involving a subpoena or third party, and decide whether OCR-assisted intake fits the rest. The flow below is the whole decision in one picture.

Decision flowchart routing a records request: verify identity, release by deadline, route subpoenas to privacy, or route fax intakeRoute by what the request is, not how it arrived. Give every request a logged due date and an owner.

Walk the path once with your own last 10 requests. Most will resolve at the first or second decision: verified identity, a straightforward copy, released inside the deadline. The ones that route further, a subpoena, a third-party disclosure, an ambiguous scan, are exactly the minority that should still land on a person's desk, not a script.

If you want a clearer read on how much of your front-desk time this actually eats, and where the biggest leak sits, the free Growth Leak Audit sizes it from your own numbers before you commit to any tool.

Fair questions.

How many days does a practice have to release medical records under HIPAA?

HIPAA's Right of Access rule gives a covered entity 30 calendar days to act on a request, starting the day it arrives. If more time is genuinely needed, the practice can take one additional 30-day extension, but only once, and only after sending the requester written notice of the reason and the new date within the original 30 days.

What can a practice legally charge for a copy of medical records?

Only a reasonable, cost-based fee: labor for copying, supplies, and postage. Search and retrieval time cannot be billed. Practices may also choose a flat fee of up to $6.50 for an electronic copy of an electronically maintained record instead of calculating actual costs. State law can set a different, often stricter, limit, so confirm your state's rule before you bill.

Does HIPAA still require 30 days, or has the deadline been shortened?

As of now, 30 days plus one 30-day extension is still the operative federal rule. A 2021 proposal to shorten it to 15 days plus a 15-day extension was never finalized, and HHS has signaled a further proposed rule on response timeframes. Confirm the current requirement before relying on any older source, and check your state law too.

What happens if a practice misses the medical records deadline?

A missed deadline is a HIPAA violation the patient can report to the HHS Office for Civil Rights, which has brought more than 50 Right of Access enforcement actions since 2019, including a $112,500 settlement in December 2025 over a 30-day delay. Most cases start with a patient complaint, not a surprise audit, so a fast fix beats a perfect one.

Can medical records release be automated safely?

The mechanical steps, logging a request, tracking the due date, and sorting incoming portal or fax requests with OCR, can be automated safely. Verifying identity and authorization, and judgment calls on subpoenas, attorneys, or third-party disclosures, should stay with a trained person. Automation should support that person's decision, not replace it, and any vendor touching PHI needs a signed BAA.

Sources

  1. [1]Individuals' Right under HIPAA to Access their Health Information (HHS Right of Access guidance)
  2. [2]Right to Access and Research FAQ (HHS.gov)
  3. [3]45 CFR 164.524, Access of individuals to protected health information (eCFR)
  4. [4]HHS Updates HIPAA Rulemaking Timeframes (Davis Wright Tremaine, Jul 2026)
  5. [5]Season of Enforcement: OCR Right of Access actions and settlements (McCarter & English)
  6. [6]HHS' Office for Civil Rights Settles HIPAA Right of Access Investigation with Concentra, Inc.
  7. [7]HIPAA Rules on Medical Records Fees: What You Can Be Charged and Your Rights
  8. [8]Rules for HIPAA and Medical Record Copy Fees (Compliancy Group)
  9. [9]12 Release of Information (ROI) Statistics for Healthcare Providers (Codes Health)
  10. [10]2026 Guide to Release of Information (ROI) & Compliance (Moxe Health)

Written by

Muhammad Qasim Hammad

Founder, Cart Gaze

Qasim builds AI receptionists and front-office automation for medical and dental practices at Cart Gaze. Posts here start from published sources and real call data, not vendor claims, and every number links back to where it came from.

Keep reading.